Threat Advisory

IBM watsonx.ai Vulnerability Exposes Users to JavaScript Injection Attacks

Threat: Vulnerability
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

IBM disclosed a moderate-severity vulnerability in its watsonx.ai platform CVE-2024-49785 that allows authenticated users to embed arbitrary JavaScript in the Web UI using unauthorized third-party LLM prompts. This cross-site scripting (XSS) flaw could result in altered functionality and credential disclosure within trusted sessions. The vulnerability affects IBM watsonx.ai on Cloud Pak for Dataand standalone installations (versions 1.1 to 2.0.3). IBM has addressed the issue with updates to version 5.1.0 and above for Cloud Pak for Data and version 2.1.0 and above for standalone installations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

IBM disclosed a moderate-severity vulnerability in its watsonx.ai platform CVE-2024-49785 that allows authenticated users to embed arbitrary JavaScript in the Web UI using unauthorized third-party LLM prompts. This cross-site scripting (XSS) flaw could result in altered functionality and credential disclosure within trusted sessions. The vulnerability affects IBM watsonx.ai on Cloud Pak for Dataand standalone installations (versions 1.1 to 2.0.3). IBM has addressed the issue with updates to version 5.1.0 and above for Cloud Pak for Data and version 2.1.0 and above for standalone installations.[emaillocker id="1283"]

 

  • CVE-2024-49785: It is a cross-site scripting (XSS) vulnerability in IBM watsonx.ai, with a CVSS score of 5.4 (Moderate). It allows authenticated users to inject JavaScript into the Web UI, risking altered functionality and credential exposure.

This vulnerability highlights the critical need for robust security in AI platforms like IBM watsonx.ai. IBM's quick response with patches emphasizes the importance of timely updates and proactive measures to safeguard data and maintain system integrity.

RECOMMENDATION:

We strongly recommend you update IBM watsonx.ai on IBM Software Hub products to version 5.1.0 and IBM watsonx.ai to version 2.1.0 and above.

REFERENCES:

The following reports contain further technical details: 
https://cybersecuritynews.com/ibm-watsonx-ai-xss-vulnerability/

[/emaillocker]
crossmenu